P2P-12
Procure to Pay
Non-PO Invoice
Detective
Manual
July 21, 2026
Control Description
Management periodically reviews the OpenText VIM authorization matrix to verify that users are assigned appropriate approval limits for non-PO invoices.
Risk
Users could retain excessive or unauthorized approval limits, allowing fraudulent or unapproved non-PO expenses to be processed and paid without proper oversight.
Implementation Details
• Authorization Matrix Definition: The OpenText VIM authorization matrix is housed in transaction /n/OPT/AR_COA (Chart of Authority), which sets user approval limits, monetary thresholds, and organizational scopes.
• Periodic Review Control: Management periodically executes a review of this matrix to ensure users maintain appropriate approval limits aligned with current job responsibilities and segregation of duties (SoD).
• Audit Evidence & Documentation: Operating the control requires retaining documented evidence of the review, such as a signed-off snapshot/export of the COA configuration or ticketing approvals for any limit modifications made during the period.
Test Procedures
Test of Design
1- Inquiry & Walkthrough: Inquire with AP Management and IT/Security owners to understand the frequency (e.g., quarterly) and methodology for reviewing user approval limits in transaction /n/OPT/AR_COA.
Test of Operating Effectiveness
1- Sample Selection: Select a sample of review periods (e.g., 2 quarterly reviews) completed during the audit period.
2- Evidence Inspection: For each sampled review, inspect the documented COA export and formal management sign-off (e.g., signed PDF or ticket approval) confirming timely review.